
WP Debugging Security & Risk Analysis
wordpress.org/plugins/wp-debuggingA support/troubleshooting plugin for WordPress.
Is WP Debugging Safe to Use in 2026?
Generally Safe
Score 93/100WP Debugging has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The static analysis of the 'wp-debugging' plugin v2.12.2 reveals a generally strong security posture in terms of direct code vulnerabilities. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, further contributes to this. The presence of nonce and capability checks is also a positive indicator of secure coding practices.
However, the plugin's vulnerability history is a significant concern. With two known CVEs, including a high-severity vulnerability and a medium-severity one, the plugin has a track record of security flaws. The fact that the last vulnerability was in early 2022 and there are currently no unpatched vulnerabilities is positive, but it doesn't negate the past issues. The common vulnerability types of Cross-Site Request Forgery (CSRF) and Missing Authorization suggest that past issues may have stemmed from insufficient input validation or access control in certain scenarios, even if the current code analysis doesn't reflect those specific weaknesses.
In conclusion, while the current version of 'wp-debugging' appears to have addressed past security issues and adheres to good coding practices for sanitization and escaping, its historical vulnerability record necessitates a cautious approach. Users should remain vigilant and ensure the plugin is always updated to the latest version to benefit from any subsequent security patches.
Key Concerns
- High severity vulnerability historically
- Medium severity vulnerability historically
- Plugin has known historical CVEs
WP Debugging Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WP Debugging <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting
WP Debugging <= 2.11.7 - Cross-Site Request Forgery
WP Debugging <= 2.10.2 - Unauthenticated Plugin Settings Update
WP Debugging Release Timeline
WP Debugging Code Analysis
Output Escaping
WP Debugging Attack Surface
WordPress Hooks 6
Maintenance & Trust
WP Debugging Maintenance & Trust
Maintenance Signals
Community Trust
WP Debugging Alternatives
Fullworks Support Diagnostics
fullworks-support-diagnostics
A diagnostic tool that helps plugin developers provide better support by collecting relevant system information and managing debug constants.
Easy PHP Settings
easy-php-settings
An easy way to manage common PHP INI settings and WordPress debugging constants from the WordPress admin panel.
Config Constants
config-constants
Modify WP_DEBUG and other WordPress constants directly in the WordPress admin rather than manually editing them via wp-config.php!
GLOBUS Debug Control
globus-debug-control
WordPress debug toolkit: filter errors, toggle WP_DEBUG, view error logs, monitor cron, transients, HTTP requests, and more.
Developer Debug Mode
developer-debug-mode
Toggle WordPress debug mode instantly. No wp-config.php editing needed. Features auto-save, admin bar quick toggle, and debug log viewer.
WP Debugging Developer Profile
13 plugins · 53K total installs
How We Detect WP Debugging
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-debugging/assets/css/wp-debugging-admin.css/wp-content/plugins/wp-debugging/assets/js/wp-debugging-admin.js/wp-content/plugins/wp-debugging/assets/js/wp-debugging-admin.js/wp-content/plugins/wp-debugging/assets/css/wp-debugging-admin.css?ver=/wp-content/plugins/wp-debugging/assets/js/wp-debugging-admin.js?ver=